ZeroHour

CVE-2026-69296

mass

Use-after-free privilege elevation in Windows Device Association Service

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

A use-after-free memory-safety flaw (CWE-416) affects the Windows Device Association Service, the built-in Windows service that handles pairing and association between the system and wired or wireless devices. Per Microsoft's rating, a credentialed, low-privilege (authorized) attacker can trigger it over the network, but only with high attack complexity, i.e., a timing/race window typical of use-after-free bugs, and with some user interaction required. Successful exploitation elevates the attacker's privileges with high impact to confidentiality, integrity, and availability, amounting to effective compromise of the target system at elevated privileges. The available data does not specify affected Windows version ranges; any Windows deployment running the Device Association Service is potentially affected, and remediation is delivered through Microsoft security updates. No exploitation is currently known: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days (43rd percentile).

What to do: Install Microsoft's security update addressing CVE-2026-69296 via Windows Update, WSUS, or your endpoint-management tooling as soon as it is available, prioritizing endpoints where low-privileged users could be induced into the required interaction. In the meantime, protect low-privileged credentials and limit untrusted network reachability to Windows hosts, since the attack requires authenticated access. Avoid disabling the Device Association Service as a workaround unless device pairing functionality is not needed.

Affected
Microsoft Windows (Device Association Service)
Estimated exposure
mass~1 billion+ Windows devices (the Device Association Service ships by default with supported Windows releases) — The Device Association Service is a default component of supported Windows client and server releases and Microsoft's Windows installed base is on the order of a billion or more active devices, so potential exposure is estimated at mass…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.